Skip to content

v0.5.1

Choose a tag to compare

@github-actions github-actions released this 30 Sep 08:08
· 15 commits to main since this release

What changed

Take this one if you pair other products with this. When a paired product
keeps using a credential it no longer holds — as a Sentry watch did after a
re-pair — the Peer link page now says which product and what to do, instead
of reporting a stranger.

Changed

  • A product still sending with a credential this installation retired is
    named on the Peer link page
    , instead of being reported as "a credential
    this installation has no record of". Re-pairing a product, or unpairing it
    here, retires its previous credential, and part of the product may not
    notice: a Sentry watch kept signing its heartbeats and its door events with
    the credential a re-pair had replaced, and every one was refused as if a
    stranger were knocking. The receipt now says whose credential it was, when
    and why it was retired, and what to do — restart the product rather than
    pair it again, which would only retire another.

Verifying this release

Every binary is signed. Verification instructions, including how to
rebuild from source and compare hashes, are in
docs/RELEASING.md.

Linux / macOS — cosign (keyless, no key to trust in advance):

cosign verify-blob notifymatrix-linux-amd64 \
  --bundle notifymatrix-linux-amd64.sigstore.json \
  --certificate-identity-regexp '^https://github\.com/suburbazine/Unifi-Notification-Matrix/' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

Download the .sigstore.json next to the binary; it carries the
signature, the certificate and the transparency-log proof. Keep
--certificate-identity-regexp — without it cosign verifies a
signature from anyone.

Build provenance (any platform):

gh attestation verify notifymatrix-linux-amd64 --repo suburbazine/Unifi-Notification-Matrix

Windows: the .exe is Authenticode-signed and timestamped.
Right-click → Properties → Digital Signatures, or:

Get-AuthenticodeSignature .\notifymatrix-windows-amd64.exe

This is source-available software under the
PolyForm Noncommercial License 1.0.0. Commercial use
requires a licence: licensing@xtremission.com

Full Changelog: v0.5.0...v0.5.1